ISC BIND 9 DNS-over-HTTPS Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in ISC BIND 9's DNS-over-HTTPS (DoH) implementation. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1. The vulnerability allows clients to exhaust a DNS resolver's CPU and memory by flooding it with crafted valid or invalid HTTP/2 traffic. As a result, the server can become overwhelmed, causing high resource usage and disrupting DoH connections for other clients.

Impact

Exploitation of this vulnerability leads to high CPU and memory usage on the affected DNS resolver, causing a denial-of-service condition. This disruption prevents legitimate clients from establishing DNS-over-HTTPS connections, significantly impairing the resolver's performance and availability of the DNS resolution service.

Remediation

Users can upgrade to BIND 9.18.33, 9.20.5, or 9.21.4. For BIND Supported Preview Edition, upgrade to version 9.18.33-S1.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
7.4
remediation
8.3
relevance
0.0
threat
0.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.